AI-powered bug bounty hunting toolkit that works with or without subscription.

OWASP Foundation web repository
A Model Context Protocol server that connects AI assistants like Claude to AWS security services, allowing them to autonomously query, inspect, and analyze AWS infrastructure for security issues and misconfigurations.
MCP server for JADX-AI Plugin

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)
BloodHound-MCP-AI is integration that connects BloodHound with AI through Model Context Protocol, allowing security professionals to analyze Active Directory attack paths using natural language instead of complex Cypher queries.
Provide AI agents with full Tor network access and dark web data through a zero-config OpenClaw skill or standalone tool.
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Security testing that runs inside the coding agent you already use. Source-available, not open source.
Policy guardrails for coding agents (Claude Code, Codex, Cursor) — every tool call is checked locally, before it runs.
Authorized security testing workspace. v2 TypeScript terminal product on release; v1 Python on pypi-release; Go branch is demo only.
The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
Modular MCP server for OPNsense firewall management - 88 tools providing access to 2000+ methods through AI assistants
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
Security testing toolkit for AI Agent: curated SecLists wordlists, injection payloads, and expert agents for authorized pentesting, CTFs, and bug bounties
Open-source adversary emulation for AI agents and MCP servers.

Deterministic safety solutions for probabilistic AI agents
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.
A plugin-based gateway that orchestrates other MCPs and allows developers to build upon it enterprise-grade agents.
✨ A customizable copilot-instructions.md ruleset & prompts to guide GitHub Copilot toward secure coding defaults in Java, Node.js, C# and Python. Blocks risky patterns, teaches safe habits.
Blackhat 2025 presentation and codebase: AI SOC agent & MCP server for automated security investigation, alert triage, and incident response. Integrates with ELK, IRIS, and other platforms.
A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained by Appsecco and licensed for remixing.
Static Code Analysis for security teams with Inter file taint analysis. Built for finding vulnerabilities, advanced structural search, derive insights and supports MCP
Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.